cachethq/cachet
An open source status page system, for everyone.
Activity
- Latest release
- 2y ago
- Total releases
- 56
- Cadence
- ~6 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Apr 18, 2015
| Version | Released | |
|---|---|---|
v2.4.1
patch
3 CVEs
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.4.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
v2.4.0
minor
3 CVEs
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.18
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.18
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
v2.3.17
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.16
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.15
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.15
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
v2.3.14
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.13
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.13
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
v2.3.12
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.12
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
v2.3.11
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.11
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
v2.3.10
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.9
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.8
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.7
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.7
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
v2.3.6
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.5
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.5
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
v2.3.4
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.4
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
v2.3.3
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.2
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.1
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.0
minor
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.0-RC6
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.0-RC6
pre
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
v2.2.4
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.2.3
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.0-RC5
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.3.0-RC5
pre
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
v2.3.0-RC4
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.0-RC3
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.0-RC2
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.3.0-RC1
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.2.2
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.2.1
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.2.0
minor
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.2.0-RC1
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.1.2
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.1.2
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v2.1.1
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v2.1.0
minor
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v2.1.0-RC2
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.1.0-RC1
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.1.0-RC1
pre
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v2.0.4
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.4
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
v2.0.3
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.3
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
v2.0.2
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.2
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
v2.0.1
patch
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.0.0
major
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.0.0-RC5
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.0-RC5
pre
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
v2.0.0-RC4
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.0.0-RC3
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.0-RC3
pre
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
v2.0.0-RC2
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.0-RC2
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
v2.0.0-RC1
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.0-RC1
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
v2.0.0-beta2
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.0-beta2
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
v2.0.0-beta1
pre
5 CVEs
CVE-2023-43661
GHSA-hv79-p62r-wg3p
Oct 16, 2023
Cachet vulnerable to Authenticated Remote Code Execution
9.1
/ 10
Critical
Network
Low
Low
None
Changed
High
Low
Low
SummaryA template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Within This vulnerability does not exist within the Twig library itself, but exists during the process of the Cachet processing of the data without any filtration. This has been patched in Cachet version 2.4. PoC
ImpactServer-side template injection is when an attacker is able to use native template syntax to inject a malicious payload into a template, which is then executed server-side. Template engines are designed to generate web pages by combining fixed templates with volatile data. Server-side template injection attacks can occur when user input is concatenated directly into a template, rather than passed in as data. This allows attackers to inject arbitrary template directives in order to manipulate the template engine, often enabling them to take complete control of the server. As the name suggests, server-side template injection payloads are delivered and evaluated server-side, potentially making them more dangerous than a typical client-side template injection. Mitigation
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
Fixed in
2.4
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2021-39165
GHSA-79mg-4w23-4fqc
Aug 30, 2021
Unauthenticated SQL Injection in Cachet
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactIn Cachet versions through 2.3.18, there is a SQL injection which is in the PatchesThe original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected. Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability. Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 42 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39174
GHSA-88f9-7xxh-c688
Aug 30, 2021
Cachet configuration leak
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret ( PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. ReferencesFurther technical details are available at https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection. For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39173
GHSA-r67m-m8c7-jp83
Aug 30, 2021
Cachet vulnerable to forced reinstall
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. PatchesThis issue was addressed by improving the middleware WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39172
GHSA-9jxw-cfrh-jxq6
Aug 30, 2021
Cachet vulnerable to new line injection during configuration edition
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactAuthenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. PatchesThis issue was addressed by improving WorkaroundsOnly allow trusted source IP addresses to access to the administration dashboard. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v0.1.0-alpha
v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.0.0-RC5
+ 44 more Show less
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-RC1
v2.1.0-RC2
v2.1.1
v2.1.2
v2.2.0
v2.2.0-RC1
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.0-RC1
v2.3.0-RC2
v2.3.0-RC3
v2.3.0-RC4
v2.3.0-RC5
v2.3.0-RC6
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.15
v2.3.16
v2.3.17
v2.3.18
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
Fixed in
2.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v2.0.0-beta1
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|